Re: [DNG] [devuan-dev] [PATCH] (security) launcher: don't attempt to execute arbitrary binaries

2020-02-14 Thread Hendrik Boom
On Thu, Feb 13, 2020 at 03:22:23PM -0800, tom wrote: > On Mon, 13 Jan 2020 10:27:40 +0100 > Evilham via Dng wrote: > > > Hello Enrico, > > > > On dt., gen. 07 2020, Enrico Weigelt wrote: > > > > > What might supposed to be convenience functionality, poses a > > > real-life > > > security threa

Re: [DNG] [devuan-dev] [PATCH] (security) launcher: don't attempt to execute arbitrary binaries

2020-02-13 Thread tom
On Mon, 13 Jan 2020 10:27:40 +0100 Evilham via Dng wrote: > Hello Enrico, > > On dt., gen. 07 2020, Enrico Weigelt wrote: > > > What might supposed to be convenience functionality, poses a > > real-life > > security threat: > > > > A user can be tricked be tricked to download malicious code,

Re: [DNG] [devuan-dev] [PATCH] (security) launcher: don't attempt to execute arbitrary binaries

2020-01-13 Thread Evilham via Dng
Hello Enrico, On dt., gen. 07 2020, Enrico Weigelt wrote: What might supposed to be convenience functionality, poses a real-life security threat: A user can be tricked be tricked to download malicious code, unpack it with +x permissions (eg. via tar) and execute it by just clicking on the i